9thwayinsignia
DevSecOps Engineer
United States - Remote
Apply through hirly
hirly scores this role against your resume, shows its reasoning, then writes a resume and cover letter for it and fills the application with you. Free to start — no card required.
hirly's read of this role
- Seniority
- Mid level
- Country
- US
- Work mode
- Remote-friendly
- First seen by hirly
- 3 Sept 2026
Derived automatically from the posting. Sign up to see how the role scores against your own resume.
the posting
9th Way Insignia is a service-disabled, veteran-owned small business bringing transformative technology to our government customers so they can achieve their missions. Our specialties include cybersecurity, cloud modernization, software development, data analytics, enterprise architecture, enterprise IT, analytics, process automation, and artificial intelligence. Learn more about 9th Way Insignia at https://9thwayinsignia.com/.
Application password: Niner
- Team (Project) Introduction
- The Department of Veterans Affairs (VA) Cybersecurity Operations Systems Engineering (COSE) project serves as an overarching technical engine that unifies Architecture and Engineering Services throughout the VA Enterprise. This program implements cohesive organizational security architecture and underlying engineering components that utilize national security standards, guidelines, and frameworks. COSE bridges the gap between high-level business requirements and technical structures, enabling the consistent deployment of secure technologies through implementation guidance and the establishment of an analytic library. Systems security engineering within COSE contributes a holistic perspective to the systems engineering effort, ensuring that stakeholder protection needs are addressed throughout the entire system life cycle from concept and development to production, support, and decommissioning. By drawing upon well-established systems engineering and security principles, COSE adapts and supplements practices to protect intellectual property, data, and the methods used to create VA systems. These activities improve the security posture of VA applications to prevent, deter, or detract from cyberattacks by nefarious adversaries or insider threats.
9 th Way Insignia is looking for an Engineer, 3, DevSecOps Engineer to join this team.
- Professional Level Information:
- An Engineer, 3 typically plans and directs research or development work on complex projects, along with engaging various parties in design and development. Costs and recommendations of new components may also involve part of the job scope. Performs multiple engineering-related tasks in various assignments within the project and firm. An Engineer, 3 oversees the design, development, implementation, and analysis of technical products and systems. An Engineer, 3 has broad knowledge of engineering procedures and assists in the resolution of complex problems. An Engineer, 3 has strong technical skills and background, a knack for learning new technologies, and a blend of good problem-solving and innovation needed to resolve a wide variety of technical production challenges.
- Functional Job (LCAT) Information:
- The DevSecOps Engineer will design, implement, automate, secure, and maintain development and deployment processes supporting the VA COSE program. The engineer will integrate cybersecurity throughout the software development lifecycle and establish automated, repeatable, and secure processes for building, testing, deploying, configuring, and maintaining applications and infrastructure within enterprise and cloud environments.
Responsibilities:
Design, implement, maintain, and optimize DevSecOps processes and CI/CD pipelines supporting secure software development, testing, integration, deployment, and operations.
Integrate security controls and security gates directly into development and deployment pipelines to ensure applications and infrastructure are securely configured, tested, and deployed.
Automate security testing and compliance activities throughout the software development lifecycle (SDLC).
Develop and maintain automated deployment scripts, workflows, and configuration-management solutions that support consistent and repeatable deployment of hardened security configurations.
Support development and implementation of cloud-native DevSecOps solutions, including secure build, test, deployment, and operational processes within cloud environments.
Support secure implementation and management of containerized applications and workloads within enterprise and cloud-native environments.
Integrate cybersecurity tools and technologies into CI/CD pipelines and DevOps workflows to identify security issues as early as possible in the development lifecycle.
Implement automated mechanisms for identifying and addressing security vulnerabilities, configuration weaknesses, compliance issues, and other software security risks.
Perform and support security assessments and vulnerability-management activities for applications, platforms, infrastructure, and cloud environments.
Support cybersecurity incident-response activities involving applications, development pipelines, cloud infrastructure, software components, and related DevSecOps technologies.
Apply secure software-development practices throughout the development lifecycle and promote security-by-design and security-by-default principles.
Manage and maintain source-code repositories and version-control processes, including Git-based repositories, branching, merging, change tracking, and controlled software releases.
Establish processes that ensure source code, configuration scripts, deployment artifacts, and other software components are appropriately version-controlled, traceable, and reproducible.
Develop and maintain automation scripts supporting build, configuration, testing, deployment, security validation, compliance, and operational activities.
Integrate automated security checks into development workflows to support continuous security validation and continuous compliance.
Support development and maintenance of automated requirements traceability from foundational cybersecurity controls and architecture requirements through implementation and final Authority to Operate (ATO).
Collaborate with cybersecurity engineers and architects to translate security requirements into automated technical controls, pipeline checks, deployment requirements, and configuration standards.
Support secure engineering activities across applications, cloud platforms, networks, data environments, identity systems, and enterprise platforms.
Review application and platform designs to identify potential security risks, control gaps, vulnerabilities, attack paths, and configuration weaknesses before implementation.
Implement and maintain secure configuration baselines and automated controls supporting consistent configuration across operating systems, cloud-native platforms, applications, databases, and other enterprise technologies.
Automate configuration and deployment processes using approved configuration-management frameworks and infrastructure automation technologies.
Support continuous quality improvement by identifying opportunities to automate manual development, security, testing, deployment, and compliance processes.
Develop automated workflows that improve the speed, repeatability, consistency, security, and reliability of software and infrastructure delivery.
Support secure integration of cybersecurity tools and enterprise technologies through APIs, automation scripts, workflow orchestration, and other approved integration methods.
Support development and maintenance of automated cybersecurity workflows, scripts, and configurations within Government-approved repositories and platforms.
Assist with security tool integration and automation to reduce manual operational workload and improve enterprise cybersecurity effectiveness.
Support software supply-chain security by helping ensure software components, dependencies, packages, patches, and other development artifacts meet applicable security and integrity requirements.
Support generation, validation, or use of Software Bills of Materials (SBOMs) where required as part of software supply-chain risk management activities.
Ensure software and patches provided for VA environments are appropriately evaluated for malware, unauthorized modificatio
Is this role actually a fit for you?
hirly answers with a score and its reasoning, then writes the resume and cover letter if you decide to go for it.
Score it against my resume